Skip to content

Branch `as-if-jh-code-sync` in JH validation project can be overwritten by mirrors

Branch as-if-jh-code-sync in JH validation project can be overwritten by mirrors. I figured this at !121531 (comment 1405701143)

This is the scenario:

Risk:

  • This branch is used to synchronize between the merge request branch and the JH corresponding branch (or main-jh), which has access to AS_IF_JH_TOKEN variable
  • This variable is a project access token which has write_repository for https://gitlab.com/gitlab-org-sandbox/gitlab-jh-validation and can be exposed to JiHu developers by the above scenario
Edited by Lin Jen-Shin